using GB5Shared.DTO.Framework.Login; using GB5Shared.ListQuery; namespace QMSDAL.Query.Matrix { // ── MatrixListGuard ──────────────────────────────────────────────────────── // Rejects list requests that omit AllocationId. // An unbounded scan across all tenants' matrices would be prohibitively // expensive and is never a valid use-case for this query. // // This guard runs before the query is built or executed, so the failure // is surfaced immediately rather than returning an empty result set or // hitting the DB with a full-table scan. // ────────────────────────────────────────────────────────────────────────── public sealed class MatrixListGuard : IQueryGuard { public void Validate(MatrixListQuery query, LoginDTO login) { ArgumentNullException.ThrowIfNull(query); ArgumentNullException.ThrowIfNull(login); if (query.Criteria is null) throw new ArgumentException( "MatrixListQuery.Criteria must be set before validation.", nameof(query)); // FIX: changed == 0 to <= 0 so the sentinel value -1 is also rejected. // A valid AllocationId is always a positive integer. if (query.Criteria.AllocationId <= 0) throw new ArgumentException( "AllocationId is required for matrix list queries.", nameof(query)); // Guard: TenantId from login must be positive. // This mirrors the check in BuildMatrixList and catches misuse early. if (login.ClientId <= 0) throw new ArgumentException( "A valid TenantId (ClientId) is required.", nameof(login)); } } }